Sceawere

Vulnerability Detail

CVE-2026-108115UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Kortix Suna SSRF via IPv6

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.9
Creation Date
3h ago
Vendor
kortix-ai
Product
suna
Attack Type
Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Kortix Suna 0.10.7 before 0.13.52 contains a server-side request forgery vulnerability that allows project managers to bypass the isPrivateIp guard by supplying IPv6 6to4 or Teredo addresses that embed private IPv4 destinations. Attackers holding project.connector.write can set connector base_url, OpenAPI, Postman, or MCP URLs to reach internal services and cloud metadata endpoints and read responses.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.9",
  "pubDate": "2026-10-10T15:16:57.270Z",
  "pubdate": "2026-10-10T15:16:57.270Z",
  "executiveSummary": "Kortix Suna versions 0.10.7 through 0.13.51 are susceptible to a Server-Side Request Forgery (SSRF) vulnerability due to an insufficient implementation of private IP address filtering.\nThe vulnerability allows authenticated users with project.connector.write privileges to bypass internal network security guards by utilizing IPv6 address encapsulation techniques.\nBy supplying specifically crafted IPv6 addresses, such as 6to4 or Teredo mappings that embed private IPv4 destinations, an attacker can coerce the application into making unauthorized requests to internal network resources.\nThe impact includes unauthorized access to internal services, sensitive internal APIs, and cloud provider metadata endpoints (e.g., AWS IMDS or GCP Metadata Server), potentially leading to information disclosure or further lateral movement.\nExploitation requires active project manager privileges within the Kortix Suna instance, making this an elevation of authority and a breach of network segmentation policy.\nThe risk is critical for environments where internal services lack robust authentication beyond IP-based allowlisting.",
  "technicalDetails": "The root cause of the vulnerability lies in a blacklist-based validation logic intended to enforce the isPrivateIp guard. The application fails to normalize IPv6 addresses effectively before applying filtering rules, specifically failing to account for tunnel-based transition mechanisms like 6to4 (RFC 3056) and Teredo (RFC 4380).\nThese IPv6 transition mechanisms allow for the embedding of IPv4 addresses within the IPv6 address space. When the server processes a base_url, OpenAPI, Postman, or MCP URL provided by a project manager, it performs a DNS resolution or direct connection attempt. Because the validation filter does not resolve or decompose these encapsulated IPv4 addresses, it incorrectly classifies them as non-private.\nThe attack flow proceeds as follows: 1) An attacker authenticates as a user with project.connector.write permissions. 2) The attacker submits a malicious configuration update, modifying a connector base_url or related integration field to a crafted IPv6 address (e.g., using 6to4 2002::/16 prefixes). 3) The application validates the input against the isPrivateIp guard; because the IPv6 string does not explicitly match restricted IPv4 ranges like 127.0.0.1 or 192.168.0.0/16, the guard returns a false negative, permitting the request. 4) The Kortix Suna backend service executes an outbound HTTP request to the embedded destination. 5) The service receives the response from the internal resource and returns the result (or an error indicating presence) back to the attacker.\nThis behavior facilitates the bypass of network-level restrictions, enabling the attacker to probe the internal infrastructure reachable from the Kortix Suna host. Successful exploitation leads to the leakage of internal service responses, which may contain configuration tokens, credentials, or metadata service data. The vulnerability is present in the application's URL processing component, which handles the integration connectors, and affects all versions from 0.10.7 up to, but not including, 0.13.52."
}
CVE-2026-108115: Kortix Suna SSRF via IPv6 (MEDIUM Severity, CVSS: 4.9) | Sceawere